VYPR

Growi

by Weseek

Source repositories

CVEs (44)

  • CVE-2025-43880MedJun 25, 2025
    risk 0.21cvss 4.3epss 0.00

    Inefficient regular expression complexity issue exists in GROWI prior to v7.1.6. If exploited, a logged-in user may cause a denial of service (DoS) condition.

  • CVE-2021-20668LowMar 10, 2021
    risk 0.18cvss 2.7epss 0.01

    Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read an arbitrary path via a specially crafted URL.

  • CVE-2022-1236MedApr 5, 2022
    risk 0.00cvss 6.5epss 0.01

    Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.

  • CVE-2021-3852HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    growi is vulnerable to Authorization Bypass Through User-Controlled Key

Page 3 of 3